Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects execution of a specific msaRAT MSI custom action that loads an embedded lib.dll payload from the MSI Binary table into memory via msiexec.exe during the InstallFinalize phase.
Detects the loading of potential Bring Your Own Vulnerable Driver (BYOVD) drivers, specifically those known to be utilized for bypassing endpoint security controls. This rule triggers on specific driver filenames or drivers loaded from non-standard, user-writable directories (e.g., %TEMP%, Public), which are common tactics for dropping and executing malicious kernel-mode code.
Detects the use of curl.exe to download an MSI file (update_ms.msi) from a remote HTTPS source into the ProgramData directory. This pattern is commonly observed in malware delivery campaigns attempting to deploy payloads in a location with lower access restrictions.
The following analytic detects the EDRSilencer-specific Windows Filtering Platform filter name "Custom Outbound Filter" when it is configured with a block action.
EDRSilencer creates WFP filters to block outbound traffic from EDR and security agent processes, impairing endpoint telemetry without requiring the tool binary to keep its original process name.
EventCode 5447 identifies creation of the runtime filter with ChangeType %%16384, while EventCode 5441 can show the same persistent filter when the Base Filtering Engine starts.
EDRSilencer creates WFP filters to block outbound traffic from EDR and security agent processes, impairing endpoint telemetry without requiring the tool binary to keep its original process name.
EventCode 5447 identifies creation of the runtime filter with ChangeType %%16384, while EventCode 5441 can show the same persistent filter when the Base Filtering Engine starts.
Detects periodic execution cycles of ERAAgent.exe that involve memory protection changes, characteristic of the SLEEPWALKER malware's XOR-decrypt-execute-reencrypt loop scheduled by a cron-like mechanism.
Detects the loading of compression libraries (such as lzma.dll or 7z.dll) by ERAAgent.exe followed by suspicious process or thread activity (e.g., remote thread creation, memory allocation). This pattern is often associated with the staging and execution of malicious payloads in memory.
Detects ERAAgent.exe (ESET Remote Administrator Agent) interacting with suspicious named pipes (e.g., mojo, spoolss) and attempts to extract credentials from command line parameters, indicating potential credential dumping or lateral movement techniques using the agent process.
Detects the ESET Management Agent (ERAAgent.exe) initiating outbound network connections using non-standard socket families, specifically AF_VSOCK (virtual socket) or VMCI (Virtual Machine Communication Interface). These interfaces are typically used for inter-process communication between a host and a guest virtual machine, or between guest virtual machines, and may indicate malicious activity such as lateral movement from a virtualized environment, virtual machine escape attempts, or unauthorized communication within an ESXi host environment.
Detects the execution of MEGAsync binaries (MEGAsync.exe, MEGAupdater.exe, or MEGAsyncSetup64.exe) from suspicious locations typically used for staging (Temp, Downloads, Public folders), or the creation of MEGAsync configuration and state cache files in the local AppData directory. This pattern is consistent with an adversary setting up a legitimate cloud storage client for data exfiltration.
Detects a high volume of file rename events initiated by a single process on a device within a short time window (5 minutes). This behavior is often indicative of ransomware activity, where files are renamed as part of the encryption or extortion process.
This is about the article "Attacking SAM and Extracting Hashes With 7z" from Hackers Arise: https://hackers-arise.com/digital-forensics-attacking-sam-and-extracting-hashes-with-7z/
This query detects instances of 7-Zip executing with elevated administrator privileges on Windows endpoints while filtering out routine background noise. It begins by capturing both live and backfilled process creation telemetry (ProcessRollup2 and SyntheticProcessRollup2) and uses a case-insensitive regular expression to identify any standard 7-Zip executable, including the command-line, GUI, and file manager binaries (7z.exe, 7za.exe, 7zg.exe, or 7zFM.exe). To pinpoint administrative activity, it filters exclusively for processes with a high integrity level decimal of 12288, indicating the binary was elevated via UAC ("Run as administrator"). It then reduces false positives by excluding automated service accounts ending in svc, Active Directory machine accounts ending in $, and the built-in SYSTEM identity. Finally, it formats the remaining high-fidelity events into a structured table displaying the timestamp, executable path, username, integrity level, and full command-line arguments for quick triage.
This query detects instances of 7-Zip executing with elevated administrator privileges on Windows endpoints while filtering out routine background noise. It begins by capturing both live and backfilled process creation telemetry (ProcessRollup2 and SyntheticProcessRollup2) and uses a case-insensitive regular expression to identify any standard 7-Zip executable, including the command-line, GUI, and file manager binaries (7z.exe, 7za.exe, 7zg.exe, or 7zFM.exe). To pinpoint administrative activity, it filters exclusively for processes with a high integrity level decimal of 12288, indicating the binary was elevated via UAC ("Run as administrator"). It then reduces false positives by excluding automated service accounts ending in svc, Active Directory machine accounts ending in $, and the built-in SYSTEM identity. Finally, it formats the remaining high-fidelity events into a structured table displaying the timestamp, executable path, username, integrity level, and full command-line arguments for quick triage.
This rule performs a two-layer hunt for the ShieldBreak/RoguePlanet (CVE-2026-50656) exploit. Layer 1 detects potential privilege escalation by identifying Windows Error Reporting processes (WerFault, WerFaultSecure, or WerMgr) running as SYSTEM that initiate suspicious child processes like cmd.exe, powershell.exe, or rundll32.exe. Layer 2 identifies the presence of known exploit artifacts including 'ShieldBreak.exe', 'Warden.dll', and the 'eicar_com.zip' test file via process execution or file creation events.
This rule detects cross-process injection techniques, such as OpenProcess, CreateRemoteThread, and memory modifications, specifically targeting 'svchost.exe' instances that do not appear to be hosting critical Windows services. By filtering out known critical services (e.g., RpcSs, DcomLaunch), the rule flags suspicious attempts to inject code into legitimate service host processes to mask malicious activity.
This rule detects in-memory patching of critical Windows security functions, specifically AmsiScanBuffer (used by AMSI) and EtwEventWrite (used by ETW). It monitors for suspicious API calls such as VirtualProtect, WriteProcessMemory, NtProtectVirtualMemory, or NtWriteVirtualMemory targeting these specific DLLs (amsi.dll and ntdll.dll), which is a common technique used by malware and offensive security tools to blind endpoint security and logging mechanisms.
This rule detects in-memory patching of critical Windows security functions, specifically AmsiScanBuffer (used by AMSI) and EtwEventWrite (used by ETW). It monitors for suspicious API calls such as VirtualProtect, WriteProcessMemory, NtProtectVirtualMemory, or NtWriteVirtualMemory targeting these specific DLLs (amsi.dll and ntdll.dll), which is a common technique used by malware and offensive security tools to blind endpoint security and logging mechanisms.
Correlates a Sysmon DriverLoad event matching known BTR.sys hashes with a subsequent System-process (PID 4) deletion of specific Defender binaries or WdFilter/WinDefend registry keys within a 10-second window — the definitive Defender self-destruction signature of the kernel primitive.
Detects outbound HTTP traffic indicative of pyCodeVx RAT check-in behavior. The rule identifies communication with ddnsfree.com C2 domains or requests containing the 'pyCodeVx' marker in the URL or User-Agent, coupled with a base64-encoded, fixed-format victim/session ID.
Detects modification of autostart extensibility point (ASEP) in registry. Adversaries may modify these keys to execute malicious code when Office files are opened.
There are various legitimate add-ins that also use these keys and this filter list might not be exhaustive.
Thus, it is recommended to review and tune filters for your environment to reduce false positives before deploying to production.
There are various legitimate add-ins that also use these keys and this filter list might not be exhaustive.
Thus, it is recommended to review and tune filters for your environment to reduce false positives before deploying to production.
Detects msedge.exe launched headless (--headless / --headless=new) with CDP remote debugging enabled (--remote-debugging-port=), a temp profile directory matching the launcher-edge- naming pattern, and window flags positioning it off-screen (--window-position=-32000,-32000, --window-size=1,1). This combination matches the TWINLOOT implant's technique of spawning a headless Edge instance with a Chrome DevTools Protocol connection, using the browser's authenticated same-origin session to proxy Microsoft Graph API C2 traffic so it blends in with legitimate browser network activity while remaining invisible on-screen. Excludes known browser-automation/CI framework parent processes and the --enable-automation flag to reduce false positives.
references:
- https://detections.ai/inspirations/01a01ade-da64-7718-8281-426118171583
- https://detections.ai/inspirations/01a01ade-d9a6-742d-8e2f-f60b5efce416
- https://detections.ai/inspirations/01a01ade-da04-700d-ba14-769eef28e475
- https://github.com/ontinue-research/threat-intel-iocs/blob/main/Public/2026-07-27-TWINLOOT-IOCs.md
- https://www.ontinue.com/resource/python-implant-hiding-its-entire-c2-inside-microsoft-365-azure/
references:
- https://detections.ai/inspirations/01a01ade-da64-7718-8281-426118171583
- https://detections.ai/inspirations/01a01ade-d9a6-742d-8e2f-f60b5efce416
- https://detections.ai/inspirations/01a01ade-da04-700d-ba14-769eef28e475
- https://github.com/ontinue-research/threat-intel-iocs/blob/main/Public/2026-07-27-TWINLOOT-IOCs.md
- https://www.ontinue.com/resource/python-implant-hiding-its-entire-c2-inside-microsoft-365-azure/
Detects AppLocker policy enumeration attempts via PowerShell using the Get-AppLockerPolicy cmdlet and an policy scope of either Effective, LDAP, or Local.
The DSInternals PowerShell Module exposes several internal features of Active Directory and Azure Active Directory.
These include FIDO2 and NGC key auditing, offline ntds.dit file manipulation, password auditing, DC recovery from IFM backups and password hash calculation.
These include FIDO2 and NGC key auditing, offline ntds.dit file manipulation, password auditing, DC recovery from IFM backups and password hash calculation.
Page 449 of 1870








